generated: '2026-08-02' method: searched source: >- openapi/threatlocker-portal-openapi-original.json plus https://threatlocker.kb.help/compliance/, https://threatlocker.kb.help/threatlocker-security-and-privacy/, https://threatlocker.kb.help/scim-integration-for-threatlocker-administrator-accounts/, https://threatlocker.kb.help/saml-integration/ standards: - id: openapi-3.0 conforms: true evidence: 'PortalAPI publishes OpenAPI 3.0.4 at https://portalapi.threatlocker.com/swagger/public/swagger.json (83 operations, 84 schemas)' - id: rest-json conforms: true evidence: All operations exchange application/json (also text/json and application/*+json) - id: api-key-auth conforms: true evidence: 'openapi components.securitySchemes: three apiKey header schemes (Authorization, ManagedOrganizationId, OverrideManagedOrganizationId)' - id: oauth2 conforms: false evidence: No oauth2 securityScheme in the spec; the PortalAPI uses portal-issued API-key tokens - id: oidc conforms: false evidence: No /.well-known/openid-configuration on any ThreatLocker host (all 404) - id: saml-2.0 conforms: true evidence: 'Portal administrator SSO via SAML with IdP group mapping to ThreatLocker user roles — https://threatlocker.kb.help/saml-integration/' - id: scim-2.0 conforms: true evidence: 'SCIM provisioning of portal administrators since Portal 3.8; SCIM provisioning fixes shipped in Portal 4.5.11 (2026-07-16) — https://threatlocker.kb.help/scim-integration-for-threatlocker-administrator-accounts/' - id: rfc9457-problem-details conforms: false evidence: No application/problem+json media type anywhere in the spec; errors are documented as bare HTTP status codes - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every ThreatLocker host - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation header support documented; no deprecated operations in the spec - id: pagination conforms: true evidence: 'Documented pageNumber/pageSize body parameters on POST search operations (https://threatlocker.kb.help/getting-started-with-threatlocker-portalapis/); pageNumber/pageSize/PageSize/PageNumber parameters present in the spec' - id: idempotency conforms: false evidence: No idempotency key header, parameter or policy documented or present in the spec - id: a2a-agent-card conforms: false evidence: No /.well-known/agent-card.json or /.well-known/agent.json on any host - id: mcp conforms: false evidence: No provider-published MCP server; only independent community servers exist - id: llms-txt conforms: true evidence: 'https://www.threatlocker.com/llms.txt returns 200 text/plain (8,262 bytes)' compliance_programs: docs: https://threatlocker.kb.help/compliance/ security_docs: https://threatlocker.kb.help/threatlocker-security-and-privacy/ audit_report_page: https://www.threatlocker.com/software-security-audit certifications: - {name: SOC 2 Type II, status: certified, evidence: 'Audited at least annually by an independent AICPA-certified auditor; report available to customers under NDA'} - {name: ISO 27001, status: in-progress, evidence: 'Stated as in progress as of March 2026; ThreatLocker states ISO 27001/2 compliance in its security documentation'} - {name: FedRAMP, status: instance-published, evidence: 'A dedicated "Portal [Instance FedRAMP]" component is published on https://threatlockerstatus.com'} frameworks_supported: - CISA Zero Trust Maturity Model v2.0 - NIST 800-171 Rev. 2 - NIST SP 800-172 - NIST 800-53 (CM-7 Least Functionality) - NIST CSF 2.0 - NIST 800-207 (Zero Trust Architecture) - CMMC 2.0 / CMMC Level 2 - PCI-DSS v4 - ISO 27001 Annex A - HIPAA Security Rule - HITRUST Control Specifications - CIS Critical Security Controls - Essential Eight Maturity Model - Cyber Essentials - NIS 2 Directive - FTC Safeguards Rule - GLBA - PIPEDA - ITAR - TISAX - CJIS Security Policy - MITRE ATT&CK Matrix - National Data Guardian's Standards for Data Security note: >- The frameworks list is what ThreatLocker states its PRODUCT helps customers satisfy (published at threatlocker.kb.help/compliance/), not certifications ThreatLocker itself holds. Only SOC 2 Type II is stated as an audit ThreatLocker itself passes. encryption: Data in transit and at rest encrypted using industry-standard protocols (per ThreatLocker security documentation) penetration_testing: Regular internal and external penetration tests (per ThreatLocker security documentation)